Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Mozilla's 'Code of Silence' Isn't
Jon Lasser, 2002-10-09

Developers are accused of not publicizing the browser's security vulnerabilities enough. But do we really need world wide alerts for every bug?

Comments Mode:
Cool a unix/lenix guy preaching the same stuff as M$crud 2002-10-09
Twinker (3 replies)
Cool a unix/lenix guy preaching the same stuff as M$crud 2002-10-09
Rob John <rdrj@mindspring.com> (2 replies)
My point was.... 2002-10-10
Twinker (1 replies)
Nothing's hidden 2002-10-15
Anonymous (1 replies)
Nothing's hidden 2002-10-15
Karl
Mozilla's 'Code of Silence' Isn't 2002-10-09
Chad Loder
Mozilla's 'Code of Silence' Isn't 2002-10-10
Jon Lasser (2 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-16
Serge Wroclawski
Unfortunately, this is unrealistic.

The problem, Jon, is twofold:

1) Who do we disclose to?

2) What measures do we take to keep the disclosures from being spread?

The first issue is, well, who is going to say that Serge can see the bug, but not Jon? Who appoints the gatekeepers?

A company with a special interest?
A project, which (as your article pointed out) also has an interest?
A third party like an OEM?
A large (and slow) organization?

Then we come to the question of by what means does the information stay hidden. An unspoken understanding? A handshake? An NDA? Threat of criminal action?

While I agree that we can sometimes do better by not disclosing a security vulnerability the minute we find one- your article didn't tackle the bigger, social and political issues that *not* disclosing them does.

- Serge Wroclawski

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/114/16815#16815
Mozilla's 'Code of Silence' Isn't 2002-10-10
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-10
Twinker (2 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-11
XandreX (1 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-11
Anonymous (2 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-14
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-15
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-12
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-12
Anonymous
Practice what you preach 2002-10-13
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-13
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-16
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus